Feed aggregator
Glider Classic Returns
Article URL: https://www.softdorothy.com/gliderclassic/gliderclassic.html
Comments URL: https://news.ycombinator.com/item?id=48947150
Points: 1
# Comments: 0
Regular expression speed and error rates
Article URL: https://www.johndcook.com/blog/2026/07/17/regex-speed-error/
Comments URL: https://news.ycombinator.com/item?id=48947143
Points: 1
# Comments: 0
Egerton MS 1995
Article URL: https://quuxplusone.github.io/blog/2026/07/16/egerton-ms-1995/
Comments URL: https://news.ycombinator.com/item?id=48947142
Points: 1
# Comments: 0
Why Org Social is the ethical Fediverse alternative
Article URL: https://en.andros.dev/blog/734c56f2/why-org-social-is-the-ethical-fediverse-alternative/
Comments URL: https://news.ycombinator.com/item?id=48947134
Points: 4
# Comments: 2
Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords
Shark’s cloud-connected robot vacuums are currently exposed by an unpatched AWS (Amazon Web Services) IoT (Internet of Things) policy flaw that could turn one compromised device into a remote-control skeleton key for many others in the same region, with access to cameras, maps, and Wi‑Fi passwords.
A researcher using the handle tokay0 took apart a Shark RV2320EDUS robot vacuum and found that its embedded AWS IoT certificate is allowed to publish and subscribe to topics for any Shark device in the same AWS Region, not just itself.
An AWS Region is a distinct geographical location where Amazon clusters its cloud data centers. Each AWS Region is completely isolated from the others. There are currently 39 AWS Regions worldwide.
By design, AWS provides per-device “shadows” that store state such as configuration and commands. However, Shark’s overly permissive Message Queuing Telemetry Transport (MQTT) policy lets a stolen certificate talk to other vacuums’ shadows as well.
Simply put, this means that each vacuum is supposed to have its own private “inbox” in the cloud. Because Shark’s cloud rules are too broad, a certificate stolen from one vacuum can also send commands to other vacuums’ inboxes.
While the certificate was extracted from the vacuum using physical access and a debug console, meaning the initial compromise requires hands‑on access, the subsequent abuse is remote and cloud‑based.
For owners, this is not just about someone starting your vacuum at 3:00 am. According to the researcher, an attacker with that cloud access could:
- Watch from the vacuum’s camera, turning it into a mobile surveillance device inside your home.
- Steal the Wi‑Fi password, which the researcher says is stored in plaintext, potentially giving them a foothold on your local network.
- Copy the vacuum’s map of your house, revealing room layouts and how frequently different areas are used.
We have seen before how “smart” vacuums can become privacy and safety risks when vendors cut corners on security. Malwarebytes Labs has covered how Ecovacs robot vacuums could be hijacked to play obscene messages and spy on users through their speakers and sensors, showing how quickly a helpful household appliance can become an unwanted house guest.
Using the certificate from his own vacuum, the researcher was able to monitor traffic from Shark devices in the same AWS Region and determine which ones supported remote command execution. During a 24‑hour period in a single AWS Region, the researcher observed 1,517,605 unique Shark serial numbers and observed 673,816 devices (about 44%) responded in a way that indicated support for the remote command execution feature.
The researcher wrote:
“It is difficult to estimate the exact number of affected devices and even more difficult to find which devices have these misconfigured certificates that allow cross-device publishing.”
But concluded that:
“A very large number of SharkNinja IoT devices are affected by this vulnerability.”
How to stay safeThe problem at the heart of this issue is a cloud-side policy that is not strict enough. That makes this a server-side problem, not a firmware bug you can patch yourself.
According to the researcher, SharkNinja has not fixed the vulnerability despite being notified more than six months ago. Until that changes, owners should:
- Put pressure on Shark to fix the issue.
- Disable remote control for the vacuum or disconnect it from Wi-Fi if you do not need its smart features.
- Watch for announcements from Shark about a fix, CVE, or recall.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
If signed off, cloud-based EPOS system will replace controversial Horizon software from Fujitsu
We visit London’s Docklands datacentre cluster, where former docks now house windowless, aluminium-clad monoliths and Telehouse South is Thames-side fortress of edge connectivity
Xkcd 3109 – Dehumidifier
Article URL: https://xkcd.com/3109/
Comments URL: https://news.ycombinator.com/item?id=48946471
Points: 1
# Comments: 0
Body Bags Found Outside OpenAI HQ as Execs Increasingly Fear for Their Lives
Article URL: https://gizmodo.com/body-bags-found-outside-openai-hq-as-execs-increasingly-fear-for-their-lives-2000786605
Comments URL: https://news.ycombinator.com/item?id=48946443
Points: 1
# Comments: 0
AI in scientific publishing: Slower, worse, and more expensive
Article URL: https://www.science.org/doi/10.1126/science.aek5570
Comments URL: https://news.ycombinator.com/item?id=48946436
Points: 1
# Comments: 0
I got tired of writing decisions on paper or notepad
Article URL: https://dcyde.app/
Comments URL: https://news.ycombinator.com/item?id=48946431
Points: 1
# Comments: 0
Browser automation CLI built for AI agents
Article URL: https://github.com/browser-act/skills
Comments URL: https://news.ycombinator.com/item?id=48946421
Points: 1
# Comments: 0
AI isn't destroying entry-level jobs
Article URL: https://www.ft.com/content/6cb9570b-dccd-46f5-b42a-4d0b7b5de35a
Comments URL: https://news.ycombinator.com/item?id=48946409
Points: 1
# Comments: 0
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up?
The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.
Show HN: A hook that stops Claude Code from re-trying fixes that failed
Article URL: https://github.com/anlor1002-alt/regressionledger
Comments URL: https://news.ycombinator.com/item?id=48946385
Points: 1
# Comments: 0
Are there words LLMs won't say?
Article URL: https://samermakes.com/blog/WCS/
Comments URL: https://news.ycombinator.com/item?id=48946384
Points: 1
# Comments: 0
US Corporate Insiders Are Selling Stocks at a Near Record Pace
Article URL: https://finance.yahoo.com/markets/stocks/articles/corporate-america-pumping-1-trillion-173100033.html
Comments URL: https://news.ycombinator.com/item?id=48946341
Points: 1
# Comments: 0
Proposed spec to share SKILL and "loop"/"Workflow" by OCI registry
Article URL: https://github.com/stumpyfr/loop-spec
Comments URL: https://news.ycombinator.com/item?id=48946308
Points: 1
# Comments: 1
How vibe coding a game made me design an AI agent protocol
Article URL: https://blog.carlid.dev/game-vibe-coding-to-protocol-design
Comments URL: https://news.ycombinator.com/item?id=48946304
Points: 1
# Comments: 0
Apple targets OpenAI employees with legal letters
Article URL: https://www.ft.com/content/1b8c9d52-88a9-426b-ba47-f1811f859166
Comments URL: https://news.ycombinator.com/item?id=48946303
Points: 3
# Comments: 1
